CVE-2018-8201: Medium severity Microsoft Windows 10 vulnerability
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8211, CVE-2018-8212, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217, CVE-2018-8221.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. No user interaction is required, but exploitation has high attack complexity.
What systems should be prioritized for remediation?
Prioritize affected Windows 10 and Windows Server 2016 systems where Device Guard Code Integrity policies are relied on to protect PowerShell sessions. A patch is available.
What is the potential impact if exploitation succeeds?
An attacker could bypass the Device Guard security feature and inject malicious code into a Windows PowerShell session. The reported impact includes low confidentiality, integrity, and availability effects.